Senior Analyst, Vulnerability Management

2 weeks ago


Singapore TikTok Full time

Responsibilities
TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices, including Los Angeles, New York, London, Paris, Berlin, Dubai, Mumbai, Singapore, Jakarta, Seoul, and Tokyo.
Why Join Us
At TikTok, our people are humble, intelligent, compassionate and creative. We create to inspire - for you, for us, and for more than 1 billion users on our platform. We lead with curiosity and aim for the highest, never shying away from taking calculated risks and embracing ambiguity as it comes. Here, the opportunities are limitless for those who dare to pursue bold ideas that exist just beyond the boundary of possibility. Join us and make impact happen with a career at TikTok.

The Global Security Organization provides industry leading security and privacy services to TikTok globally. Our organization uses four principles that guide our strategic and tactical operations. First, we champion trust and transparency, leading the charge in organizational transparency and execution of security and privacy capabilities that drive customer trust. Second, we are a business catalyst and enabler, embodying the DNA of technical innovation. Third, We drive risk informed and empowered decision making, giving our business leaders the information needed to make key decisions. Finally, we proactively identify and reduce risk while enabling innovative product development - to consistently build sustainable world-class security capabilities.
The Vulnerability Management Senior Analyst is tasked with the day to day activities of the Vulnerability Management Team. They schedule, conduct, and regularly review vulnerability scans, analyzing for key risks and escalating where needed. They should be aware of current policies and procedures and ensure they are being followed properly. The senior analyst should have hands on experience with vulnerability management tools and be able to mentor and advise other team members.

**Tasks and Responsibilites**:

- Continuously log and track remediation activities of discovered vulnerabilities throughout the environment
- Evaluate vulnerabilities based on prioritization criteria
- Investigate persistent vulnerabilities
- Coordinate and communicate with cross-functional teams throughout the VM lifecycle
- Generate and distribute operational-level reports
- Facilitate exception handling and escalation
- Support regulatory compliance monitoring and reporting
- Review and optimize scan templates to ensure complete coverage of environment
- Support treatment and remediation activities with identified points of contact and system owners
- Provide risk analysis for identified vulnerabilities and system change requests
- Develop processes and document procedures for use by other team members and to enhance efficiencies
- Maintain regular communication with Vulnerability Management Lead and organizational management for collaboration, process optimization, tools tuning, and information sharing

**Qualifications**:
**Minimum Qualifications**:

- Bachelor’s Degree or industry equivalent work experience in vulnerability management in a security program
- Approximately 5-7 years of applicable experience
- Hands on operational experience with vulnerability management tools (e.g. Qualys, Nexpose) including the ability to deploy, configure, and run these tools.
- Knowledge of vulnerability scoring systems (e.g. CVSSv3)
- Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions.
- Ability to handle large datasets and perform vulnerability analysis
- Ability to work alongside other security functions to determine vulnerability scoring and impact
- Ability to examine issues both strategically and analytically.
- Ability to work collaboratively in a team environment
- Excellent communication skills (verbal and written)
- Strong analytical and problem-solving skills
- Detail oriented, organized, follow up skills with an analytical thought process
- Project management experience

**Preferred Qualifications**:

- CISSP, CISM, or equivalent certification
- Familiarity with vulnerability management across SaaS and IaaS cloud platforms (e.g., AWS, Google Cloud, etc.)
- Working knowledge/experience with Python, SQL and REST APIs
- Ability to handle ambiguity and collaborate with a global team
- Ability to coach junior staff and contractors

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.



  • Singapore TikTok Full time

    Responsibilities TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices, including Los Angeles, New York, London, Paris, Berlin, Dubai, Mumbai, Singapore, Jakarta, Seoul, and Tokyo. Why Join Us At TikTok, our people are humble, intelligent, compassionate and creative. We...


  • Central Singapore Emprego SG Full time

    **Location** Singapore, Central Singapore **Job Type** Permanent **Salary** $7,500 - $15,000 Per Month **Date Posted** 8 minutes ago Additional Details **Job ID** 49525 **Job Views** 2 **Job Description**: Roles & Responsibilities **It’s Time** Allen & Overy is a leading global law firm operating in over thirty countries. By turning our...


  • Singapore NTT Full time

    Vulnerability Management Operations Analyst (Cybersecurity Assurance)Location: Tanjong Pagar, Singapore Employment Type: 12 Months Contract We are hiring a Mid-Level/Senior Vulnerability Management Operations Analyst to support cybersecurity assurance work for a key financial organisation. Key Responsibilities Manage vulnerability lifecycle end-to-end...


  • Singapore Income Insurance Limited Full time

    Responsibilities Perform vulnerability scanning/discovery, tracking of remediation SLA and follow up on closure of findings Support private bug bounty and public vulnerability disclosure program by performing triaging and follow up on reports received Coordinate with external vendors on penetration testing program Conduct meetings to communicate the findings...


  • Singapore Income Insurance Limited Full time

    **Responsibilities**: - Perform vulnerability scanning/discovery, tracking of remediation SLA and follow up on closure of findings - Support private bug bounty and public vulnerability disclosure program by performing triaging and follow up on reports received - Coordinate with external vendors on penetration testing program - Conduct meetings to...

  • Vulnerability Analyst

    2 weeks ago


    Singapore Continental Full time

    **Company Description** Continental develops pioneering technologies and services for sustainable and connected mobility of people and their goods. Founded in 1871, the technology company offers safe, efficient, intelligent and affordable solutions for vehicles, machines, traffic and transportation. In 2022, Continental generated sales of €39.4 billion and...

  • Vulnerability Analyst

    2 weeks ago


    Singapore Continental Full time

    Your tasks **Responsibilities**: - Work with scanning tools to identify vulnerabilities - Manually verify and identify vulnerabilities - Prioritize vulnerabilities - Continuously improve the automation process - Support asset owners in understanding vulnerabilities and selecting appropriate remediation measures - Track vulnerability remediation - Stay up...


  • Singapore Centre for Strategic Infocomm Technologies (CSIT) Full time

    Cyber Security Vulnerability Researcher (Network Devices)Join to apply for the Cyber Security Vulnerability Researcher (Network Devices)role at Centre for Strategic Infocomm Technologies (CSIT)Cyber Security Vulnerability Researcher (Network Devices)3 weeks ago Be among the first 25 applicants Join to apply for the Cyber Security Vulnerability Researcher...


  • Singapore TENTEN Partners Pte. Ltd. Full time

    **An eminent Asian banking institution is seeking a seasoned Vulnerability Management Specialist to fortify its cybersecurity operations. If you're a driven leader with expertise in threat and vulnerability management, this could be your opportunity to make a substantial impact.** **Responsibilities**: - Own and drive a comprehensive vulnerability...


  • Singapore Seatrium Full time $80,000 - $120,000 per year

    JOB DESCRIPTIONKnow the vulnerability management lifecycle, including identification, assessment, reporting, prioritization, and remediation.Lead the development, implementation, and continuous improvement of vulnerability management processes and tools.Serve as the subject matter expert (SME) for vulnerability risk, patching standards, and remediation...